The terms under which TrueWatch processes personal data on behalf of customers.
This Data Processing Agreement (the “DPA”) sets out the terms governing the processing of the Personal Data by TRUEWATCH TECHNOLOGY INC PTE. LTD. (“TrueWatch”, “we”, “us”, or “our”) on behalf of the customer (the “Customer” or the “User”).
This DPA forms part of and is incorporated into the service agreement, or other written or electronic agreement, between TrueWatch and the Customer that references this DPA (the “Agreement”). In the event of any conflict between this DPA and the Agreement, this DPA shall prevail in respect of TrueWatch's processing of Personal Data as a processor on behalf of the Customer. This DPA does not vary the limitations and exclusions of liability in the Agreement.
1. Introduction
This DPA applies to the extent that TrueWatch processes the Personal Data on behalf of the Customer in connection with the Services under the Agreement.
The parties acknowledge that, for the purposes of the Data Protection Laws, the Customer acts as the Data Controller or the Data Processor (as applicable), and TrueWatch acts as the Data Processor when processing the Customer Personal Data on behalf of the Customer.
This DPA sets out the parties’ respective rights and obligations with respect to the processing, security, and confidentiality of the Customer Personal Data.
This DPA takes effect on the effective date of the Agreement and continues until TrueWatch ceases to process Customer Personal Data. Clauses 7, 8, 9, 10 and 11 survive termination.
2. Definitions
The following definitions apply to this DPA:
“Account Data” means the Customer information provided to TrueWatch relating to the creation or management of their TrueWatch account, such as the first and last name of authorized users, billing contact information, username and email address.
“AI Service Terms" means the TrueWatch AI Service Terms referenced in or incorporated into the Agreement, as amended from time to time.
“CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, together with its implementing regulations. "Business", "Business Purpose", "Consumer", "Personal Information", "Sell", "Share" and "Service Provider" have the meanings given to them in the CCPA.
“Customer Data” means data submitted, transmitted, accessed, displayed, or otherwise processed from or on behalf of the Customer’s environment through the Services. The Customer determines the type and quantity of Customer Data through the configuration and use of the service.
“Customer Personal Data” means the Customer Data that contains personal data, as defined under applicable data protection laws.
“Data Controller” means the entity that determines the purposes and means of the processing of the Personal Data. For the purposes of this DPA, the Customer acts as the Data Controller or the Data Processor, as applicable.
“Data Processor” means the entity that processes the Personal Data on behalf of the Data Controller. For the purposes of this DPA, TrueWatch acts as the Data Processor when processing the Customer Personal Data on behalf of the Customer.
“Data Protection Laws” means all data protection and privacy laws applicable to a Party's processing of Personal Data under this DPA, including the Singapore Personal Data Protection Act 2012 (the "PDPA"), and, where applicable to a Party's processing, the GDPR, the UK GDPR and any other applicable data protection or privacy law, in each case as amended, supplemented or replaced from time to time.
“Device” means any mobile phone, tablet, personal computer, or other hardware used to access or use the Services.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
“Data Subject” means the natural person to whom the personal data relates.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Personal Data Breach” means a security breach that occurs during the transmission, storage or other processing of the Customer Personal Data by TrueWatch, resulting in accidental or unlawful destruction, loss, alteration or unauthorized disclosure of or access to the Customer Personal Data.
“Process” and “Processing” means any operation or set of operations which is performed on personal data, including but not limited to collection, recording, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, transfer, and deletion.
"SCC" means the Standard Contractual Clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time. For transfers subject to the UK GDPR, the SCCs are incorporated as varied by the UK International Data Transfer Addendum (the "UK Addendum").
“Services” means the hosted products, mobile applications, APIs, AI-enabled features, integrations, notifications, support, and related services provided by TrueWatch to the Customer under the Agreement.
“Sub-processor” means any processor engaged by TrueWatch or its affiliates to process the Customer Personal Data on behalf of TrueWatch or its affiliates while providing services.
“TrueWatch” means TRUEWATCH TECHNOLOGY INC PTE. LTD., the party to this DPA.
“TrueWatch Mobile” means any mobile application made available by or on behalf of TrueWatch for accessing or using the Services, including any iOS or Android application.
3. Role Assignment
3.1 Processor Role
a. The parties acknowledge that, to the extent TrueWatch processes the Customer Personal Data on behalf of the Customer in connection with the Services, TrueWatch acts as the Data Processor.
b. TrueWatch shall process Customer Personal Data only:
i. in accordance with the Agreement, this DPA (including Appendix A), and the Customer’s documented instructions (the “Instructions”); and
ii. as otherwise required by applicable law.
iii. Customer instructs TrueWatch to process Customer Personal Data as necessary to provide, maintain, and support the Services, including through the web platform, TrueWatch Mobile, APIs, integrations, notifications, and other service interfaces, as configured and used by Customer.
iv. TrueWatch shall inform the Customer if, in TrueWatch's opinion, an Instruction infringes the Data Protection Laws, provided that TrueWatch is under no obligation to conduct a legal review of the Instructions or of the Customer Personal Data.
3.2 Controller Role
TrueWatch acts as an independent Data Controller with respect to personal data for which it determines the purposes and means of processing, including Account Data, billing data, service usage data, mobile application diagnostic data, crash data, Device information, notification-related data, and data relating to website visitors, sales, and marketing activities.
3.3 Customer Responsibilities
a. Customer is responsible for ensuring that:
i. it has all necessary rights, permissions, and legal bases to provide the Customer Personal Data to TrueWatch for processing;
ii. its Instructions comply with the Data Protection Laws; and
iii. it provides all required notices to, and obtains all required consents from, the Data Subjects, where applicable.
b. Customer is solely responsible for:
i. the accuracy, quality, and legality of the Customer Personal Data;
ii. the means by which the Customer acquires such data; and
iii. Customer’s configuration and use of the Services, including any data collection, masking, filtering, notification, access control, mobile access, and processing settings.
3.4 AI Services
a. Where the Customer enables the TrueWatch AI Services (including Toby AI Copilot and Toby AI Agents, where made available), TrueWatch processes Customer Personal Data as Data Processor in accordance with this DPA and the AI Service Terms.
b. AI model providers and AI infrastructure providers engaged by TrueWatch are Sub-processors and are subject to Clause 5.
c. TrueWatch does not use Customer Personal Data to train generalized or foundation models, except where separately agreed with the Customer in writing.
d. The Customer determines the data scope, tool scope, permissions, operating mode and approval controls applicable to Agentic Actions, and remains responsible for the legal basis for, and any notices required in respect of, such processing.
e. TrueWatch personnel may review AI interactions only as necessary to provide, secure and troubleshoot the Services, subject to the access controls in Appendix B.
4. Data Security
4.1 Security Measures
a. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to individuals, TrueWatch implements and maintains appropriate technical and organizational measures designed to protect the Customer Personal Data, as further described in Appendix B.
b. Customer acknowledges that:
i. the security measures implemented by TrueWatch are appropriate to the risk presented by the processing; and
ii. the secure use of the Services, including appropriate configuration and access management, remains the Customer’s responsibility.
4.2 Personal Data Breach
a. TrueWatch maintains incident detection and response procedures designed to address security incidents and Personal Data Breaches.
b. TrueWatch shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Customer Personal Data. Where the information required is not available at the time of notification, TrueWatch may provide it in phases as it becomes available, without further undue delay. Such notification shall include, to the extent reasonably available:
i. a description of the nature of the Personal Data Breach, including the categories of Data Subjects and the approximate scope;
ii. the likely consequences of the Personal Data Breach;
iii. the measures taken or proposed to address the Personal Data Breach;
iv. where appropriate, recommendations for the Customer to mitigate potential adverse effects; and
v. the name and contact details of TrueWatch's data protection officer or other contact point from whom further information can be obtained.
c. TrueWatch shall provide such further information and reasonable assistance as the Customer requires to meet its own notification obligations within the periods prescribed by the Data Protection Laws applicable to it.
d. The Customer acknowledges that notification of a Personal Data Breach by TrueWatch does not constitute an admission of fault or liability.
e. TrueWatch shall not be required to notify any regulatory authority or any Data Subject on the Customer's behalf unless required by applicable law or expressly agreed in writing.
4.3 Baseline Standard
TrueWatch applies, as a minimum standard across all Customer Personal Data it processes, technical, organisational and contractual measures that are no less protective than those required of a data processor under Articles 28, 32 and 33 of the GDPR, irrespective of whether the GDPR applies to the processing. Where the Data Protection Laws applicable to the Customer impose a stricter or additional requirement, that requirement prevails to the extent of the difference.
4.4 Assistance with Assessments
Taking into account the nature of the processing and the information available to it, TrueWatch shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with a supervisory authority where required under the Data Protection Laws. TrueWatch may charge a reasonable fee for assistance that goes beyond the information made available under Clause 8.
5. Sub-processor
5.1 Authorization
a. Customer provides a general authorization for TrueWatch to engage the Sub-processors to process the Customer Personal Data.
b. TrueWatch maintains a list of its Sub-processors and will make such list available to the Customer. TrueWatch may update its Sub-processors from time to time and will provide at least thirty (30) days' prior notice of any new Sub-processor, including via email, in-product notification, TrueWatch Mobile notification, or other reasonable means, where available.
5.2 Objection to the Sub-processor
a. Customer may object to a new Sub-processor on reasonable, documented data protection grounds by notifying TrueWatch in writing at [email protected] within 15 calendar days of receiving notice.
b. If the Customer raises a valid objection that cannot be reasonably resolved, TrueWatch may, at its option:
i. provide a commercially reasonable alternative; or
ii. terminate the affected portion of the Services without liability.
5.3 Sub-processor Obligations
a. TrueWatch shall enter into agreements with the Sub-processors that impose data protection obligations no less protective than those set out in this DPA, to the extent applicable to the services performed.
b. TrueWatch remains responsible for the performance of its Sub-processors in accordance with this DPA.
6. Data Subject Rights
6.1 Assistance
Taking into account the nature of the processing, TrueWatch shall provide reasonable assistance to the Customer to enable the Customer to respond to requests from the Data Subjects exercising their rights under the Data Protection Laws, to the extent the Customer cannot address such requests through its use of the Services.
6.2 Direct Requests
If TrueWatch receives a request from the Data Subject relating to the Customer Personal Data, TrueWatch will:
a. advise the Data Subject to submit the request directly to the Customer; and
b. notify the Customer of the request, where reasonably identifiable, without undue delay.
6.3 Customer Responsibility
Customer is solely responsible for responding to the Data Subject requests and for complying with the Data Protection Laws in relation to such requests.
7. Data Deletion
7.1 Deletion Upon Termination
a. Upon termination or expiration of the Agreement, TrueWatch will delete or, at the Customer's election, return the Customer Personal Data within thirty (30) days, unless applicable law requires retention.
b. Customer acknowledges that deletion may occur automatically as part of such processes and that the Customer is responsible for submitting any specific deletion requests, where applicable, within a reasonable period following termination.
7.2 Backup and Residual Data
Unless otherwise required by applicable law, Customer Personal Data archived in backups will be isolated and protected from any further processing and will be deleted, overwritten or rendered inaccessible when the relevant backup expires in accordance with TrueWatch's backup cycle. Where applicable law requires TrueWatch to retain Customer Personal Data beyond that period, TrueWatch will retain it only for so long as that requirement subsists, and this DPA shall continue to apply to the retained data.
7.3 Customer Responsibility for Data Export
a. The Customer is solely responsible for exporting or retrieving the Customer Personal Data prior to termination or expiration of the Agreement.
b. Following termination and the applicable retention period, TrueWatch shall have no obligation to maintain or provide access to the Customer Personal Data and will delete such data in accordance with its standard practices and the Data Protection Laws.
7.4 Data Outside TrueWatch’s Control
TrueWatch's deletion and return of Customer Personal Data under this DPA applies only to Customer Personal Data held by TrueWatch within the Services. The Customer remains responsible for any copies stored outside TrueWatch’s possession or control, including on user devices, customer systems, exports, screenshots, or third-party services.
8. Audit
8.1 Audit Reports
a. Upon the Customer’s reasonable written request and subject to the confidentiality obligations under the Agreement, TrueWatch shall make available information reasonably necessary to demonstrate compliance with this DPA, including summaries or excerpts of relevant third-party audit reports or certifications (such as SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, or equivalent).
b. Such information shall be provided not more than once in any twelve (12)-month period, unless required by applicable law or following a confirmed Personal Data Breach affecting the Customer Personal Data.
c. All audit rights under this Clause shall be exercised in a manner that does not unreasonably interfere with TrueWatch’s business operations, systems, or security, and shall be limited strictly to the processing of the Customer Personal Data in connection with the Services.
8.2 Scope Limitation
a. Any audit materials provided shall be strictly limited to information relevant to the processing of Customer Personal Data in connection with the Services and shall not include:
i. confidential information of other customers;
ii. internal security architecture, penetration testing details, or other information that could compromise the security or integrity of TrueWatch’s systems; or
iii. information subject to legal, regulatory, or contractual restrictions.
b. TrueWatch shall have no obligation to permit on-site audits, remote audits, or inspections unless required by applicable law.
c. To the extent an audit is required by applicable law, such audit shall be:
i. conducted upon at least two (2) months' prior written notice, or such shorter notice as may be required by applicable law or by a competent regulatory authority;
ii. subject to mutually agreed scope and timing;
iii. performed during normal business hours; and
iv. carried out in a manner that minimizes disruption to TrueWatch’s operations.
d. Customer shall bear its own costs in connection with any audit and shall reimburse TrueWatch for any reasonable costs incurred in supporting such audit, unless otherwise required by applicable law.
9. International Data Transfer
9.1 General Authorization
The Customer authorizes TrueWatch and its Sub-processors to transfer the Customer Personal Data across jurisdictions as necessary to provide the Services, secure, support, monitor, and improve the Services, including transfers outside Singapore and outside the jurisdiction in which the Customer is established.
9.2 Transfer Mechanisms
a. To the extent that a transfer of Customer Personal Data is subject to a restriction on international transfers under the Data Protection Laws, the parties shall ensure that at least one of the following mechanisms applies to that transfer:
i. an adequacy decision, finding, or equivalent determination by a competent authority in respect of the recipient country;
ii. the SCCs, as incorporated under Clause 9.3, where the transfer is subject to the GDPR;
iii. the UK Addendum, where the transfer is subject to the UK GDPR;
iv. Section 26 of the PDPA and Regulation 10 of the Personal Data Protection Regulations 2021, for transfers of Customer Personal Data out of Singapore; or
v. any other transfer mechanism valid under the applicable Data Protection Laws.
b. Where the SCCs apply under Clause 9.2(a)(ii), execution of the Agreement shall constitute execution of the SCCs and their annexes. Appendix A serves as Annex I and Appendix B serves as Annex II. Annex III does not apply, as the parties have adopted the general written authorization option under Clause 9 of the SCCs.
c. Where more than one mechanism is available, the mechanism listed earliest in Clause 9.2(a) shall apply, unless the parties agree otherwise in writing.
9.3 Application of Standard Contractual Clauses (where applicable)
Where the SCCs apply:
a. Module 2 (Controller to Processor) shall apply, or, where the Customer acts as a processor on behalf of a third-party controller, Module 3 (Processor to Processor) shall apply. The Customer warrants that it has the authority of the relevant controller to enter into the SCCs on that controller's behalf;
b. Clause 7 (Docking Clause) shall apply;
c. Clause 9 (Use of Sub-processors): Option 2 (general written authorization) shall apply, with prior notice as set out in Clause 5.1;
d. Clause 11 (Remedies): the optional language shall not apply;
e. Clause 17 (Governing Law): the SCCs shall be governed by the law of Ireland;
f. Clause 18 (Jurisdiction): disputes shall be resolved before the courts of Ireland;
g. Annex I and Annex II shall be deemed completed with the information set out in Appendix A and Appendix B of this DPA.
9.4 Flexibility of Transfer Mechanisms
a. TrueWatch may implement alternative or supplementary transfer mechanisms where appropriate to ensure compliance with the Data Protection Laws, without requiring amendment to this DPA, provided that such mechanisms maintain a level of protection for the Personal Data consistent with applicable legal requirements.
b. Where the Data Protection Laws applicable to a transfer require a specific transfer mechanism, filing, assessment or form of contractual clauses, the parties shall cooperate in good faith to put that mechanism in place, and shall execute such additional documents as are reasonably required. The Customer shall be responsible for any filing or assessment required of it as controller, and TrueWatch shall provide reasonable assistance.
9.5 Controller Data
a. For the avoidance of doubt, this Clause 9 applies to transfers of the Customer Personal Data processed by TrueWatch as the Data Processor.
b. Transfers of personal data processed by TrueWatch as an independent Data Controller (including the Account Data) shall be governed by the Data Protection Laws and TrueWatch’s Privacy Notice (https://www.truewatch.com/privacy-policy).
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except in respect of liability that cannot be limited under applicable law or under Clause 12 of the SCCs where those apply.
11. Order of Precedence
In the event of any conflict or inconsistency between the documents, the following order of precedence shall apply: (1) SCCs (where applicable); (2) this DPA, in respect of TrueWatch's processing of Personal Data as a processor; (3) the AI Service Terms, in respect of matters specific to the TrueWatch AI Services; (4) the Agreement.
12. Amendments
a. TrueWatch may update this DPA from time to time where:
i. such update is required to comply with applicable laws, regulations, or regulatory guidance; or
ii. such update is commercially reasonable, does not materially reduce the level of protection for the Customer Personal Data, and does not materially adversely affect the Customer’s rights under this DPA.
b. Where required, TrueWatch will provide notice of material updates through reasonable means (including email or in-product notification).
13. California Personal Information
13.1 Application and Roles
This clause applies only where and to the extent the CCPA applies to the Customer's processing. In that case the Customer is a Business and TrueWatch is a Service Provider. Customer Personal Data that constitutes Personal Information is made available to TrueWatch solely for the limited and specified Business Purposes described in Appendix A and in the Agreement.
13.2 Restrictions
TrueWatch shall not:
a. sell or share the Personal Information;
b. retain, use or disclose the Personal Information for any purpose other than the Business Purposes specified in Clause 13.1, including for any commercial purpose other than those Business Purposes, or outside the direct business relationship between the parties, except as permitted by the CCPA; or
c. combine the Personal Information with personal information received from or on behalf of any other person, or collected from TrueWatch's own interaction with a Consumer, except as permitted for a Service Provider under the CCPA.
13.3 Level of Protection
TrueWatch shall comply with the obligations applicable to a Service Provider under the CCPA and shall provide the same level of privacy protection to the Personal Information as the CCPA requires of a Business. TrueWatch acknowledges that it understands the restrictions in Clause 13.2 and will comply with them.
13.4 Oversight, remediation and notification
The Customer may take reasonable and appropriate steps, including the exercise of its rights under Clause 8, to ensure that TrueWatch uses the Personal Information in a manner consistent with the Customer's obligations under the CCPA, and reasonable steps to stop and remediate any unauthorized use. TrueWatch shall notify the Customer without undue delay after determining that it can no longer meet its obligations under the CCPA.
13.5 Sub-processors
TrueWatch may engage Sub-processors in accordance with Clause 5, and shall impose on each Sub-processor that processes Personal Information written obligations that are substantially equivalent to those in this Clause 13.
13.6 Consumer requests
TrueWatch shall assist the Customer in responding to verifiable Consumer requests in accordance with Clause 6. Where TrueWatch receives a request directly from a Consumer, it shall handle it in accordance with Clause 6 and shall not respond on the Customer's behalf.
13.7 Other United States privacy laws
Where the privacy law of another United States state applies to the Customer's processing, TrueWatch acts as a processor or service provider (however described under that law) and the obligations in this DPA shall apply to that processing to the extent that law requires equivalent contractual terms.
Appendix A: Data Processing Detail
1. List of Parties
1.1. Data Exporter (Customer):
Name: Customer.
Address: The address associated with the Customer’s TrueWatch account, or as otherwise specified in the Agreement.
Contact Details: The contact details associated with the Customer’s TrueWatch account, or as otherwise specified in the Agreement.
Data Transfer Activities: Processing of the Customer Personal Data as necessary to provide, maintain and support the Services, and to perform TrueWatch's obligations and exercise its rights under the Agreement.
Role: Customer acts as the Data Controller or the Data Processor, as applicable, in respect of the Customer Personal Data.
Execution: Execution of the Agreement shall constitute execution of this Appendix A.
1.2. Data Importer (TrueWatch):
Name: TRUEWATCH TECHNOLOGY INC PTE. LTD
Address: 55 Ubi Ave 3 #02-07 Aspial One, Singapore 408864
Contact Details: As specified in the Agreement. Privacy inquiries may be directed to: [email protected]
Data Transfer Activities: Processing of the Customer Personal Data as necessary to provide, maintain and support the Services, and to perform TrueWatch's obligations and exercise its rights under the Agreement.
Role:
• TrueWatch acts as the Data Processor when processing the Customer Personal Data on behalf of the Customer.
• TrueWatch acts as an independent Controller for the Account Data and other data processed for its own legitimate business operations (including billing, security, service improvement, mobile application diagnostics, crash reporting, notification delivery, and compliance).
Execution:
Execution of the Agreement shall constitute execution of this Appendix A.
1.3. Data Importer (TrueWatch):
Where the SCCs apply, the competent supervisory authority is the supervisory authority of the EEA Member State in which the Customer is established or, where the Customer is not established in the EEA, the supervisory authority of the Member State in which the Data Subjects whose personal data is transferred are located. For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office.
2. Data Transfer Description
2.1. Categories of Data Subjects
Data subjects may include the Customer's employees, customers, suppliers, and end users, as determined and controlled by the Customer.
2.2. Categories of Personal Data
Personal data submitted, stored, accessed, displayed, transmitted, or otherwise processed by the Customer through the Services, including through the web platform, TrueWatch Mobile, APIs, integrations, and notifications. The nature and scope of such personal data is determined by the Customer.
2.3. Sensitive Data
The Customer Personal Data may include sensitive data only where the Customer elects to process such data through the Services.
TrueWatch does not require or intend to process sensitive data and shall process such data only in accordance with the Customer’s documented instructions and applicable law.
2.4. Frequency of Transfers
Personal data is transferred on a continuous basis during the provision of the Services.
2.5. Nature of Processing
Processing operations necessary to provide the Services, including collection, recording, organization, structuring, storage, retrieval, access, display, use, transmission, notification delivery, support, troubleshooting, and deletion, as configured and controlled by the Customer, and in accordance with the Agreement. Where the Customer enables the AI Services, processing also includes automated analysis of Customer Personal Data, generation of outputs, and execution of actions within the permissions and operating mode configured by the Customer.
2.6. Purpose of Processing
To provide, maintain and support the Services, and to perform TrueWatch's obligations and exercise its rights under the Agreement.
2.7. Retention Period
Retained in accordance with the Customer's documented instructions, including as configured within the Services, and subject to applicable system retention policies and legal obligations.
Appendix B: Technical and Organizational Security Measures
TrueWatch implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to such data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to individuals.
1. Encryption and Key Management
a. TrueWatch maintains encryption mechanisms and cryptographic key management policies and procedures designed to ensure the secure generation, storage, rotation, and use of cryptographic keys.
b. The Customer Personal Data is encrypted in transit over public networks using industry-standard encryption protocols.
c. The Customer Personal Data is encrypted at rest within TrueWatch systems using industry-accepted encryption standards, where applicable to the relevant system and processing environment.
2. Security Certifications and Assessments
a. TrueWatch holds ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 certifications, within the scope stated in the applicable certificates.
b. TrueWatch obtains a SOC 2 Type II report on a recurring basis, within the scope stated in the report.
c. Summaries, certificates or reports may be made available to the Customer in accordance with Clause 8.
d. TrueWatch may substitute a successor or equivalent standard, and will notify the Customer if a certification or report lapses and is not renewed or replaced.
3. Access Control
a. Access to the Customer Personal Data is restricted to authorized personnel based on the principle of least privilege and a need-to-know basis.
b. TrueWatch maintains authentication and access control mechanisms, including provisioning and de-provisioning processes, to ensure timely and appropriate access management. Access through TrueWatch Mobile and other service interfaces is subject to authentication, authorization, and access control measures appropriate to the relevant interface.
4. Business Continuity and Disaster Recovery
a. TrueWatch maintains business continuity and disaster recovery plans designed to support the availability and resilience of the Services.
b. Such plans are periodically tested and updated, and include measures to restore availability and access to Customer Personal Data in a timely manner in the event of an incident.
5. Change Management and Vulnerability Management
a. TrueWatch maintains change management procedures governing updates to systems, infrastructure, and services to ensure security and operational integrity.
b. TrueWatch conducts periodic security testing, which may include penetration testing and vulnerability assessments, in accordance with its internal security policies and risk management framework.
c. Identified vulnerabilities are prioritized and remediated based on severity in accordance with TrueWatch’s internal risk management and vulnerability management processes.
d. Security patches and updates are applied in accordance with documented procedures, with priority given to critical vulnerabilities.
6. Data Security and Segregation
a. TrueWatch implements technical and organizational measures to ensure the confidentiality, integrity, and availability of the Customer Personal Data.
b. The Customer Personal Data is logically segregated within TrueWatch systems to prevent unauthorized access between customers.
7. Governance and Risk Management
a. TrueWatch maintains an information security program, which is reviewed and updated periodically.
b. TrueWatch conducts risk assessments at regular intervals to identify and mitigate security risks.
c. TrueWatch maintains incident detection and response procedures designed to address security incidents in a timely and effective manner.
d. Where the AI Services are enabled, TrueWatch maintains records of AI interactions, approvals and executed actions in accordance with the AI Service Terms.
8. Personnel Security and Training
a. TrueWatch implements personnel security measures, which may include background screening where permitted by applicable law, for personnel with access to the Customer Personal Data. Personnel authorized to access Customer Personal Data are bound by confidentiality obligations.
b. Personnel receive security and data protection training upon onboarding and periodic refresher training thereafter.
9. Evolution of Security Measures
a. TrueWatch may update or modify the technical and organizational security measures described in this Appendix from time to time in its discretion, provided that such updates or modifications are designed to maintain or enhance the overall security of the Services.
b. Such updates may reflect changes in technology, industry practices, regulatory requirements, or the nature of the Services, and may include the implementation of alternative or successor measures.
c. For the avoidance of doubt, the security measures described in this Appendix are intended to describe the current security framework and do not limit TrueWatch’s ability to implement additional, different, or more advanced security measures.
